Collected research
XSSing client-side dynamic HTML includes by hiding HTML inside images and more
Argues that sites which fetch a URL fragment by Ajax and drop it into innerHTML are vulnerable even without HTML5 cross-origin requests, because every same-origin file becomes HTML. HTML hidden after a JPEG's end-of-image marker survives and executes when the image is rendered as markup, and poisoned User-Agent strings in server logs give the same effect.
Record
- Researcher
- lava
- Published by
- blog.andlabs.org
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of lava, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .